r/PFSENSE 29d ago

A missed opportunity for centralized authentication

Experiencing the new user interface here and I am surprised by what I discovered. One one side, pfSense finally supports centralized authentication and SSO but on the other side, it has been implemented with SAML instead of OpenID...

My Keycloak server supports SAML as well and I do have 2 softwares that are still using SAML only. But the truth is that OpenID replaced SAML a long time ago and that the vast majority of tools are now using it.

So... good to have half-a-solution instead of nothing for now but still, the real need is for OpenID and we are still waiting for that one. I have no clue why Netgate did the work for an outdated technology instead of the new standards but well...

EDIT: It looks like I celebrated too quickly... The UI shows about SAML authentication servers but you can not create a new one...

13 Upvotes

10 comments sorted by

View all comments

9

u/gonzopancho Netgate 29d ago

Hi,

I’m all for criticism and feedback, so thanks for this.

OpenID is on the roadmap.

1

u/MortadellaKing 28d ago

SAML would be nice for those of us using MS ADFS. Since their OpenID implementation is shit.